Korean LawSAFE
korean-law-mcp
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
국가법령정보센터 Open API를 활용한 고성능 MCP (Model Context Protocol) 서버입니다.
AI 에이전트(Claude Desktop, Cursor 등)가 실시간으로 한국 법령, 판례, 행정규칙을 검색하고 분석할 수 있도록 합니다.
✨ 주요 기능
🔍 법령 검색
- 키워드 기반 법령 검색: 민법, 상법, 근로기준법 등 다양한 법령 검색
- 법령 상세 조회: 특정 법령의 전문(조문) 및 상세 정보 조회
- 법령 기본 정보: 소관부처, 공포일자, 시행일자, 개정 정보 포함
⚖️ 판례 검색
- 판례 키워드 검색: 손해배상, 계약, 부당해고 등 판례 검색
- 판례 상세 조회: 판결요지, 판시사항, 판례 전문 조회
- 법원 필터링: 대법원, 헌법재판소 등 법원별 필터링 지원
- 참조조문/판례: 관련 법령 및 참조 판례 정보 제공
📋 행정규칙 검색
- 행정규칙 검색: 각 부처의 행정규칙 검색
- 소관부처 정보: 제정일자, 시행일자 등 상세 정보
🚀 성능 최적화
- 전략적 캐싱: 법령/판례 데이터를 24시간 캐싱하여 API 호출 최소화
- 빠른 응답 속도: 캐시 기반 즉시 응답
- 안정적인 운영: 에러 핸들링 및 로깅 시스템
🎯 활용 사례
법률 전문가
- 계약서 검토: AI가 계약서를 분석하고 관련 법령 및 판례를 자동 참조
- 법률 자문: 특정 사안에 대한 관련 법령 및 판례를 즉시 조회
- 판례 연구: 유사 판례를 빠르게 검색하고 비교 분석
기업 법무팀
- 기업 컴플라이언스: 사업 관련 법령을 실시간 조회
- 노무 관리: 근로기준법 등 노동 관련 법령 및 판례 검색
- 소송 준비: 관련 판례 및 법령 자동 수집
스타트업/개발자
- 서비스 법률 검토: 개인정보보호법, 전자상거래법 등 관련 법령 확인
- 약관 작성: 관련 법령을 참조하여 약관 작성
- 법률 리스크 분석: AI가 서비스 기획서를 분석하고 관련 법률 리스크 파악
일반 사용자
- 법률 상담: AI 에이전트를 통한 기본적인 법률 정보 조회
- 권리 확인: 소비자 권리, 임차권 등 관련 법령 및 판례 검색
- 민원 준비: 행정심판, 소송 준비를 위한 법률 정보 수집
🛠️ 기술 스택
- MCP Framework: FastMCP
- Data Validation: Pydantic
- HTTP Client: Requests
- XML Parsing: xml.etree.ElementTree
- Caching: cachetools (24시간 TTL)
- Async Processing: asyncio
- Environment: Python-dotenv
📦 설치 및 설정
1) 의존성 설치
pip install -r requirements.txt
💡uv를 사용하는 경우:uv sync
2) API 키 발급
국가법령정보센터 Open API 키를 발급받아야 합니다:
- 국가법령정보센터 Open API 사이트 방문
- 회원가입 및 로그인
- 공동활용 서비스 > Open API 메뉴에서 API 신청
- 승인 후 인증키(OC) 발급받기
📌 참고: API 키 발급은 보통 즉시 승인되며, 무료로 이용 가능합니다.
3) 환경 변수 설정
프로젝트 루트에 .env 파일을 생성하고 API 키를 설정합니다:
cp env.law.example .env
.env 파일 내용:
LAW_API_KEY=your_law_api_key_here LOG_LEVEL=INFO PORT=8096
4) 서버 실행
0d1dc7ed2c0aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add korean-law-mcp --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GOOGLE_API_KEY=${GOOGLE_API_KEY} --env LAW_API_KEY=${LAW_API_KEY} -- uvx korean-law-mcp{
"mcpServers": {
"korean-law-mcp": {
"command": "uvx",
"args": [
"korean-law-mcp"
],
"env": {
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"GOOGLE_API_KEY": "${GOOGLE_API_KEY}",
"LAW_API_KEY": "${LAW_API_KEY}"
}
}
}
}Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_law_detail_tool | read | |
get_precedent_detail_tool | read | |
health | read | 서비스 상태 확인 |
search_administrative_rule_tool | read | |
search_law_tool | read | |
search_precedent_tool | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
&& rm -rf /var/lib/apt/lists/*
fastmcp, uvicorn, pydantic, python-dotenv, requests, beautifulsoup4, lxml, cachetools
cat .env
Gates applied: no_behavioural_pass, no_license.
0d1dc7ed2c0afull audit observations/trust-audit/mcp-server/seonaru__korean-law.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 0d1dc7ed2c0a | SAFE | B | 89 | first audit |
Questions
What is the Korean Law MCP server?
korean-law-mcp
What tools does Korean Law expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Korean Law safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Korean Law need?
It reads GEMINI_API_KEY, GOOGLE_API_KEY and LAW_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (0d1dc7ed2c0a), read on 2026-10-07. The repository is watched and re-audited when it changes.